Skip to main content

CWE archive

CWE-289 CVEs

Programmatic archive

36 CVEs tagged with CWE-2898 Critical, 18 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2026-9701

Published Jul 8, 2026

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the passw…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-55075

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chaine…

CVSS 7.4 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-48618

Published Jun 26, 2026

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname…

CVSS 6.5 · Medium
evidence mentions
16
Buzz score
41.3
Vendor/product tagsBeta · best-effort

CVE-2026-56091

Published Jun 25, 2026

When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. This vulnerability is similar to…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53622

Published Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenti…

CVSS 7.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-50627

Published Jun 12, 2026

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-44492

Published Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 addr…

CVSS 8.6 · High
evidence mentions
45
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-43617

Published May 20, 2026

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attac…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-39858

Published Apr 30, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's Fo…

CVSS 7.8 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-3184

Published Apr 3, 2026

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before set…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-32036

Published Mar 19, 2026

OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authentication checks by manipulating /api/…

CVSS 8.3 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-23903

Published Feb 9, 2026

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fi…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24058

Published Jan 22, 2026

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-55130

Published Jan 20, 2026

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directorie…

CVSS 9.1 · Critical
evidence mentions
20
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-14777

Published Dec 16, 2025

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetSer…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2025-13613

Published Dec 10, 2025

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin not properly logging in a us…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-64521

Published Nov 19, 2025

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creat…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64343

Published Nov 7, 2025

(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 and below, the installation directory inherits permissions…

CVSS 7.8 · High

CVE-2025-60375

Published Oct 9, 2025

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and pass…

CVSS 7.3 · High

CVE-2025-41248

Published Sep 16, 2025

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics…

CVSS 7.5 · High

CVE-2025-8415

Published Aug 20, 2025

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Networ…

CVSS 5.9 · Medium

CVE-2025-29266

Published Mar 31, 2025

Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use…

CVSS 9.6 · Critical

CVE-2024-11283

Published Mar 14, 2025

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56511

Published Jan 10, 2025

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55634

Published Dec 10, 2024

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2